CompTIA Network+ (N10-009)Network SecurityMedium
A network administrator is reviewing logs and discovers that a large number of ICMP echo requests are flooding the network, specifically targeting a critical server. The source IP addresses appear to be legitimate internal hosts, but the server is becoming unresponsive. What type of attack is most likely occurring?
- ASQL Injection
- BVLAN Hopping
- CEvil Twin
- DSmurf Attack
Show answer & explanationAnswer & explanation
Correct answer: D. Smurf Attack
A Smurf Attack involves an attacker sending a large number of ICMP echo requests with the victim's IP address spoofed as the source, causing all hosts on the network to reply to the victim, overwhelming it.
Why the other options are wrong
- A. SQL Injection is an attack against databases through web application vulnerabilities.
- B. VLAN Hopping allows an attacker to gain access to traffic on different VLANs.
- C. An Evil Twin attack involves a rogue access point mimicking a legitimate one to intercept wireless traffic.
Smurf Attack
A type of distributed denial-of-service (DDoS) attack in which an attacker floods a target server with ICMP echo replies.
- Uses ICMP echo requests (ping) to broadcast addresses.
- Victim's IP address is spoofed as the source address.
- Amplifies traffic as all hosts on the network reply to the victim.
Memory trick: Smurfs make a big noise with tiny pings.